using System;
using System.Data;
using System.Configuration;
using System.Collections;
using System.Web;
using System.Web.Security;
using System.Web.UI;
using System.Web.UI.WebControls;
using System.Web.UI.WebControls.WebParts;
using System.Web.UI.HtmlControls;
using Microsoft.Practices.EnterpriseLibrary.Data;
using Microsoft.Practices.EnterpriseLibrary.Data.Sql;
using System.Data.SqlClient;
using System.Data.Common;

public partial class AddDatabaseNote : System.Web.UI.Page
{
    Microsoft.Practices.EnterpriseLibrary.Data.Database db = DatabaseFactory.CreateDatabase("Application_Data");

    protected void Page_Load(object sender, EventArgs e)
    {
        if (!IsPostBack)
        {
            if (Convert.ToBoolean(Session["sAdministrator"].ToString()) == false)
            {
                Response.Redirect("~/AccessDenied.aspx");
            }

            this.lblInstanceName.Text = Request.QueryString["InstanceName"].ToString();
            this.lblDatabaseName.Text = Request.QueryString["DatabaseName"].ToString();
            this.lblCreateDate.Text = System.DateTime.Now.ToShortDateString();
            this.lblCreatedBy.Text = Session["sFullUserName"].ToString();
        }

    }
    protected void btnCancel_Click(object sender, EventArgs e)
    {
        Response.Redirect("~/DatabaseDetail.aspx?InstanceName=" + this.lblInstanceName.Text.ToString() + "&DatabaseName=" + this.lblDatabaseName.Text.ToString());
    }
    protected void btnAddNote_Click(object sender, EventArgs e)
    {
        DbCommand dbCommand = db.GetSqlStringCommand("INSERT INTO DatabaseNote (InstanceName,DatabaseName,CreatedBy,Note) VALUES(" +
                                             "'" + this.lblInstanceName.Text.ToUpper() + "'," +
                                             "'" + this.lblDatabaseName.Text.ToString() + "'," +
                                             "'" + User.Identity.Name.ToString() + "'," +
                                             "'" + this.txtNote.Text.ToString() + "')");

        db.ExecuteNonQuery(dbCommand);

        Response.Redirect("~/DatabaseDetail.aspx?InstanceName=" + this.lblInstanceName.Text.ToString() + "&DatabaseName=" + this.lblDatabaseName.Text.ToString());
        
    }
}
